Most enterprises have large networks with security devices scattered all over the network landscape, and those devices generate gigabytes of logs every day. Capturing these logs and searching through them for debugging is easy. It's much harder to use the information from those security devices to create actionable intelligence about the threats affecting your network. That's the job of a security information management product.
In this video, network security expert Joel Snyder offers an overview of what SIMs are, what they do and how they support a security information lifecycle that can augment an enterprise's defensive capabilities. Specific technical points of emphasis will include:
- Collection
- Alerting
- Reporting
- Forensics